Cybersecurity NIST Controls Implementation

56,000+ 
State Employees Served
41+
Agencies Under Enterprise IT
$390M+
Annual IT Budget
$48M+
Prior Ransomware Incident Cost

Building Security Foundations Across 13 Mission-Critical Systems for a State Enterprise IT Organization 

Situation

Situation

A ransomware attack on a state health agency disrupted critical public services for months, cost over $48 million in direct remediation, and forced the state’s central IT organization to run the cyber incident command center. The event exposed a systemic vulnerability: none of the enterprise IT platforms serving 56,000+ employees across 41+ state agencies had been systematically reviewed or remediated for security. The state legislature responded with comprehensive cybersecurity legislation mandating NIST framework adoption, biennial security assessments, and centralized cyber governance. The central IT organization needed to rapidly mature its security posture across mission-critical cloud and enterprise platforms — while establishing a sustainable, compliant security program from the ground up. 
What NXT Delivered

What NXT Delivered

NXT implemented a comprehensive cyber remediation program leveraging the NIST Risk Management Framework across 13 mission-critical statewide systems and 70 critical controls: 
  • Executed all six NIST RMF steps: Categorize, Select, Implement, Assess, Authorize, Monitor 
  • Established system baselines, SOPs, risk assessments, and change impact analysis processes 
  • Scaled delivery through a POD structure — expanding from 1 pilot to 4 operational PODs  
  • Deployed MFA, automated account lifecycle management, and encryption 
  • Created repeatable methodology and comprehensive documentation for long-term sustainability 

Key Outcomes

NXT implemented a comprehensive cyber remediation program leveraging the NIST Risk Management Framework across
13 mission-critical statewide systems and 70 critical controls:

01

Completed security baseline

across 13 mission-critical systems with security controls implemented and hundreds of vulnerabilities remediated 
02

88% reduction in session hijacking risk 

through enforced timeouts, session limits, and secure termination 
03

MFA deployed across critical platforms

including systems where authentication had been absent entirely 
04

Audit-ready compliance

with state cybersecurity legislation and NIST 800-53 standards — securing the enterprise infrastructure serving 56,000+ employees statewide 
Discuss a similar challenge with NXT